GHSA-wcmm-28rg-mg3r

Suggest an improvement
Source
https://github.com/advisories/GHSA-wcmm-28rg-mg3r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wcmm-28rg-mg3r
Aliases
Published
2022-05-17T02:01:32Z
Modified
2025-04-12T02:27:09Z
Summary
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
Details

phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not properly handle the absence of the (1) README, (2) ChangeLog, and (3) LICENSE files, which allows remote attackers to obtain the installation path via a direct request for a nonexistent file.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-04-12T01:47:30Z",
    "nvd_published_at":  "2011-02-14T22:00:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.11.0
Fixed
2.11.11.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json"

Packagist / phpmyadmin/phpmyadmin

Package

Name
phpmyadmin/phpmyadmin
Purl
pkg:composer/phpmyadmin/phpmyadmin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.3.0
Fixed
3.3.9.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wcmm-28rg-mg3r/GHSA-wcmm-28rg-mg3r.json"